1、对安全有威胁的注册表位置WINDOWS自动启动键值详解贴出(规则支持通配符*),供大家参考:自动运行-HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionRun*HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionRun*HKEY_LOCAL_MACHINESystem*controlset*ControlSessionmanagerBootExecuteHKEY_CURRENT_USERSoftwareMicrosoftWindowsntCurrentversionWindo
2、wsloadHKEY_CURRENT_USERSoftwareMicrosoftWindowsntCurrentversionWindowsrunHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionPoliciesExplorerRun*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionPoliciesExplorerRun*HKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindowsSystemScripts*HKEY_CURRENT_
3、USERSoftwareMicrosoftWindowsCurrentversionExplorerShellfoldersStartupHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionRunonce*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionRunonce*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionRunonceex*HKEY_LOCAL_MACHINESoftwareMicrosoftWin
4、dowsCurrentversionRunservices*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionExplorerShellfoldersCommonStartupHKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionExplorerUsershellfoldersCommonStartupHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionExplorerUsershellfoldersStartupHK
5、EY_LOCAL_MACHINESoftwareMicrosoftWindowsntCurrentversionInifilemapping*驱动/服务相关-HKEY_LOCAL_MACHINESystem*controlset*Services*HKEY_LOCAL_MACHINESystem*controlset*Services*imagepathHKEY_LOCAL_MACHINESystem*controlset*ControlSafeboot*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionShellserviceob
6、jectdelayload*文件关联-HKEY_CLASSES_ROOTExefileShellOpenCommand*HKEY_CLASSES_ROOTComfileShellOpenCommand*HKEY_CLASSES_ROOTBatfileShellOpenCommand*HKEY_CLASSES_ROOTPiffileShellOpenCommand*HKEY_CLASSES_ROOT.bat*HKEY_CLASSES_ROOT.cmd*HKEY_CLASSES_ROOT.exe*HKEY_CLASSES_ROOT.txt*HKEY_CLASSES_ROOT.pif*HKEY_CL
7、ASSES_ROOTTxtfileShellOpenCommand*HKEY_CLASSES_ROOT.com*HKEY_CLASSES_ROOTComfile*HKEY_CLASSES_ROOT.reg*HKEY_CLASSES_ROOTRegfileShellOpenCommand*HKEY_CLASSES_ROOT.inf*HKEY_CLASSES_ROOTInffileShellOpenCommand*HKEY_CLASSES_ROOT.hlp*HKEY_CLASSES_ROOTHlpfileShellOpenCommand*HKEY_CLASSES_ROOT.chm*HKEY_CLA
8、SSES_ROOTChm.fileShellOpenCommand*网络保护-HKEY_LOCAL_MACHINESystem*controlset*ServicesWinsock2*HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionPoliciesNetwork*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionPoliciesNetwork*HKEY_LOCAL_MACHINESystem*controlset*ServicesTcpipParametersDataBa
9、sePathHKEY_LOCAL_MACHINESystem*controlset*ServicesTcpipParametersInterfaces*HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindowsWindowsupdate*HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindowsfirewall*HKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindowsWindowsupdate*HKEY_CURRENT_USERSoftwarePoliciesMicro
10、softWindowsfirewall*HKEY_LOCAL_MACHINESystemCurrentcontrolsetServicesSharedaccessParametersFirewallpolicy*特殊注册表项目-HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsntCurrentversionWindowsAppInit_DLLsHKEY_LOCAL_MACHINESystem*controlset*ControlSessionmanager*FileRenameOpe.HKEY_CURRENT_USERControlpanelDon;tloa
11、d*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionControlpanelDon;tload*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionPoliciesSystem*HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionPoliciesSystem*HKEY_CURRENT_USERControlpanelDesktopscrnsave.exeHKEY_LOCAL_MACHINESoftwareMicro
12、softWindowsntCurrentversionImagefileexecutionoptions*HKEY_LOCAL_MACHINESoftwareMicrosoftSecuritycenter*HKEY_LOCAL_MACHINESoftwarePoliciesMicrosoftWindowsSaferCodeidentifiers0Paths*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionExplorerShellexecutehooks*HKEY_CURRENT_USERSoftwareMicrosoftComm
13、andprocessorAutorunHKEY_LOCAL_MACHINESoftwareMicrosoftCommandprocessorAutoRunHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionPolicies*HKEY_CLASSES_ROOTClside6fb5e20-de35-11cf-9c87-00aa005127ed*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsntCurrentversionWinlogonNotify*HKEY_LOCAL_MACHINESoftwareM
14、icrosoftWindowsCurrentversionExplorerSharedtaskscheduler*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsntCurrentversionSvchost*浏览器保护-HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerExtensions*HKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerExtensions*HKEY_CURRENT_USERSoftwareMicrosoftInternetexplor
15、erMenuext*HKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerToolbar*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionExplorerBrowserhelperobjects*HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerstylesstylesheetHKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternetexplorerToolbarsRestrictions*H
16、KEY_CURRENT_USERSoftwarePoliciesMicrosoftInternetexplorerInfodeliveryRestrictions*HKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerMainStartPageHKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerMainDefault_Page_U.HKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerMainLocalPageHKEY_LOCAL_MACHINESo
17、ftwareMicrosoftInternetexplorerMainStartPage_bakHKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerMainHOMEOldSPHKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerMainSearchPageHKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerMainDefault_Search_.HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMa
18、inStartPageHKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMainDefault_Page_U.HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMainLocalPageHKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMainStartPage_bakHKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMainHOMEOldSPHKEY_CURRENT_USERSoftwareMi
19、crosoftInternetexplorerMainSearchBarHKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMainUseCustomSea.HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMainSearchPageHKEY_USERS.defaultSoftwareMicrosoftInternetexplorerMainSearchPageHKEY_USERS.defaultSoftwareMicrosoftInternetexplorerMainSearchBarHKEY
20、_LOCAL_MACHINESoftwareMicrosoftInternetexplorerSearchCustomizeSearchHKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerSearchSearchAssistantHKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerSearchDefault_Search_.HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionInternetsettingsZonemapRanges*H
21、KEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionInternetsettingsZonemapRanges*HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionInternetsettingsMinLevelHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionInternetsettingsSafetyWarningL.HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentver
22、sionInternetsettingsTrustWarningLe.HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionInternetsettingsSecurity_RunActiv.HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentversionInternetsettingsSecurity_RunScri.HKEY_USERS.defaultSoftwareMicrosoftWindowsCurrentversionInternetsettingsMinLevelHKEY_USE
23、RS.defaultSoftwareMicrosoftWindowsCurrentversionInternetsettingsSafetyWarningL.HKEY_USERS.defaultSoftwareMicrosoftWindowsCurrentversionInternetsettingsSecurity_RunActiv.HKEY_USERS.defaultSoftwareMicrosoftWindowsCurrentversionInternetsettingsSecurity_RunScri.HKEY_USERS.defaultSoftwareMicrosoftWindows
24、CurrentversionInternetsettingsTrustWarningLe.HKEY_CLASSES_ROOTProtocolsFilter*HKEY_CLASSES_ROOTProtocolsHandler*HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerSearchurl*HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerUrlsearchhooks*HKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerAdvancedopti
25、ons*HKEY_LOCAL_MACHINESoftwareMicrosoftActivesetupInstalledcomponents*HKEY_LOCAL_MACHINESoftwareMicrosoftCodestoredatabaseDistributionunits*流氓及恶意程序保护-HKEY_CLASSES_ROOTCns*HKEY_CURRENT_USERSoftware3721*HKEY_LOCAL_MACHINESoftware3721*HKEY_LOCAL_MACHINESoftwareClassesCns*HKEY_LOCAL_MACHINESoftwareMicro
26、softWindowsCurrentversionRunHelper.dll*HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMenuext!搜一搜*HKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerAdvancedoptions!cns*HKEY_LOCAL_MACHINESystemControlset*EnumRootLegacy_cnsmink*HKEY_LOCAL_MACHINESystemControlset*ServicesCnsminkp*HKEY_CLASSES_ROOTA
27、ssist*HKEY_CLASSES_ROOTAutolive*HKEY_CURRENT_USERSoftwareMicrosoftInternetexplorerMainCns*HKEY_CLASSES_ROOTAdkiller*HKEY_LOCAL_MACHINESoftwareClassesAdkiller*HKEY_LOCAL_MACHINESoftwareMicrosoftInternetexplorerActivexcompatibility1b0e7716-898e-4.*HKEY_CLASSES_ROOTCoolbar*HKEY_LOCAL_MACHINESoftwareCla
28、ssesCoolbar*HKEY_CURRENT_USERSoftwareYahoo*HKEY_LOCAL_MACHINESoftwareYahoo*HKEY_CLASSES_ROOTZschkfile*HKEY_CLASSES_ROOTEbay*HKEY_USERSS-1-5-*SoftwareMicrosoftInternetexplorerMenuext*ebay*HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentversionRunEbay*HKEY_CLASSES_ROOTApplicationsPig*HKEY_LOCAL_MACHINESoftwareClassesApplicationsPig*HKEY_LOCAL_MACHINESoftwareMiranda*HKEY_USERSS-1-5-*So
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1